Red Hat Security Advisory: OpenShift Container Platform 4.12.2 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-4235 — go-yaml: Denial of Service in go-yaml CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be
🎯 Affected products124
- Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:1328c4e7944b6d8eda40a8f789471a1aec63abda75ac1199ce098b965ec16709_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:7df4ec15985cc7f2c7e65121bf96807964c141564c853db97e99189d1e5d053d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:91485ea897e7e7e63a4f1c832ecb3e00b0d88880c39c567cc6793aba6a319542_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:9f589bc3172c30fc13e067b67561dca131077270aa4f363c0d64e36baa727d82_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:9960468ac74560b54c199f89acc9e480d21d5a830a5fd0f94f26b80d906df228_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:b8fec71b6229b3cbc42d7dbd0431addee4239eb4e13201fe18a05b5c4784634c_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:ccbd05cc54773003101861ae9ff0bb0cbd0c1aef9947f87cc5cc697b4eb9e9a7_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:fda5b08ab89f252597c84fa996e602d543aaf02b399b9f2ec5487e14053292ef_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1ee82fd37878788339b25ea3571477f9f46f27912693dfda87365608284531d3_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3bf7d28bbd7cc09ed334043794be1ad885955eae715a23eae9cf06f73bc7531e_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4f82595e4b704728e739a40be8dcefec7e5054bcfc14ac10f972de6c0e099275_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:e5e923f9377d4d93ea62eaa925d8e82a163c67cd3e76b5bbf173a0ae8ed9c471_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:3565885ba61eae836bf607f68bb8cdc02cdf62130e2b8a8c4f021748b0e1bbdf_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:563e84476d67967e4c6f04f4f41d2b44028d1047eab5aa68ccb460e4561f3643_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:ac141fe0efaca367020946ef4d867d4e6a4d9495860bace4b3343ca376f1a734_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:b791282794caa461ca6ad0ed67a6e74e6f8996c9f9d13b7d282a8b7f7ad045a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:3837c818dbb83ed55c3c6b629c07fff20b819a8004ef850265bc8b0d8b75fcd7_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:6d361dd7384890d5d1887af77dcea37c3b47b232b9038d4040b45e202bae7793_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:8cd8b5e28bd16099d1f01145fc84c09193bbcd92efa0ed3d60b66a402cc01cca_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:be4eb59b697c457c7630c0481b39b0e47b671049ba604f9c9d8a27badf5fa724_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:2d85b3176ce85586adfbb575bd38ca657fdbdf96ebfe7bda967deebf29c88aae_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:01bb99d6bb65a11366c450d8a00848f9bdc88badf2b5d7423b08b630c0494f37_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:93410b6d19c76b6e35dea1e5ffcec85b28b5044df8e8a98ea736fc2fa0ded55f_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:942937a23d6d2fad89e130b0f7a77327529f36aa8de7687df15ff258d1a3af26_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-installer-rhel8@sha256:aea43e71dcd3b511d8e7c5d03e9c0b35422b610edf3773406a510e31dbe1fefc_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:156a06636a074e36238556f1a7e8c40ef252b168ed8cfdc0bcace37e9b56877a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:20b2b202577b8cceb5bf6b2159ba20c4b0cfc72dd8c51119bb34613227cec17a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:653f4c019000f9e2d3af2e57c18b0a7cb41a6dfefa4c7a14bdacc7c0546000c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:7707067772fefcae012f1f16155301679b3d87bc6531540822d116780419e572_s390x as a component of Red Hat OpenShift Container Platform 4.12
- +94 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:31c7741fc7bb73ff752ba43f5acf014b8fadd69196fc522241302de918066cb1 (For s390x architecture) The image digest is sha256:a3eff5b631aab76c1e66b88fd6fbfc75dcef31a2ced76786b53a1c6afadecb12 (For ppc64le architecture) The image digest is sha256:78b979f9f93d636d2a1650ae0f38e758c5bb2bccd9e0485cd4adc9a7acc5a38a (For aarch64 architecture) The image digest is sha256:d237aca1231b23e4c4ffa8d9d4c0fd429be7c1ed7b685681ae50fb2588c0f223 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2023:0569
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156729
- externalhttps://issues.redhat.com/browse/OCPBUGS-2174
- externalhttps://issues.redhat.com/browse/OCPBUGS-4678
- externalhttps://issues.redhat.com/browse/OCPBUGS-5493
- externalhttps://issues.redhat.com/browse/OCPBUGS-5509
- externalhttps://issues.redhat.com/browse/OCPBUGS-5743
- externalhttps://issues.redhat.com/browse/OCPBUGS-5745
- externalhttps://issues.redhat.com/browse/OCPBUGS-5976
- externalhttps://issues.redhat.com/browse/OCPBUGS-6052
- externalhttps://issues.redhat.com/browse/OCPBUGS-6179
- externalhttps://issues.redhat.com/browse/OCPBUGS-6489
- externalhttps://issues.redhat.com/browse/OCPBUGS-6493
- externalhttps://issues.redhat.com/browse/OCPBUGS-6517
- externalhttps://issues.redhat.com/browse/OCPBUGS-6600
- externalhttps://issues.redhat.com/browse/OCPBUGS-6678
- externalhttps://issues.redhat.com/browse/OCPBUGS-6743
- externalhttps://issues.redhat.com/browse/OCPBUGS-6755
- externalhttps://issues.redhat.com/browse/OCPBUGS-6822
- externalhttps://issues.redhat.com/browse/OCPBUGS-6836
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0569.json